CVE-2023-2275

The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'get_item', 'get_order_notes' and 'add_order_note' functions in versions up to, and including, 1.5.3. This makes it possible for authenticated attackers with subscriber privileges or above, to view the order details and order notes, and add order notes.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wclovers:woocommerce_multivendor_marketplace:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2023-06-09 06:16

Updated : 2023-11-07 04:12


NVD link : CVE-2023-2275

Mitre link : CVE-2023-2275

CVE.ORG link : CVE-2023-2275


JSON object : View

Products Affected

wclovers

  • woocommerce_multivendor_marketplace
CWE

No CWE.